HTTP Client Vulnerability in Axios Affects Multiple Versions
CVE-2026-101906
8.2HIGH
What is CVE-2026-101906?
Axios, a promise-based HTTP client used in both browser and Node.js environments, is susceptible to a denial of service through a crafted redirect. A flaw in the handling of the HTTP_PROXY or HTTPS_PROXY environment variables when no_proxy is non-empty allows malicious actors to exploit the hostname processing. This occurs when redirect locations with an excessive number of trailing dots cause quadratic backtracking in regular expression processing, potentially blocking the Node.js event loop. This vulnerability impacts all versions from 1.15.0 to 1.20.0, and users are encouraged to upgrade to the patched version 1.20.0 to mitigate the risk.
Affected Version(s)
axios >= 1.15.0, < 1.20.0
